Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerable dependency lodash.trim #33

Open
kradical opened this issue May 9, 2023 · 0 comments
Open

Vulnerable dependency lodash.trim #33

kradical opened this issue May 9, 2023 · 0 comments

Comments

@kradical
Copy link

kradical commented May 9, 2023

We recently got a dependabot alert about a vulnerability in lodash.trim. It hasn't been released in 7 years so I don't know if we should expect to see a new release? A better alternative might be to drop lodash.trim. I'll take a peak and see how reasonable that would be.

Edit: it seems like likely replacing trim ends up doing regular expression stuff in this repo, possibly exposing a similar regex dos type vulnerability. So maybe wait and see and upgrade.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant